1. X
  2. Arsen Security
Log inSign up
Arsen Security
295 posts
Image
user avatar
Arsen Security
@arsen
πŸ›‘οΈ Security Awareness for the age of AI β€” ✨ AI-driven vishing, smishing, and phishing β€” 🌐 arsen.co
πŸ‡ΊπŸ‡Έ USA πŸ‡¬πŸ‡§ UK πŸ‡«πŸ‡· France
arsen.co/en
Joined March 2020
197
Following
364
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

TermsΒ·PrivacyΒ·CookiesΒ·AccessibilityΒ·Ads InfoΒ·Β© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
  • user avatar
    Arsen Security
    @arsen
    Jul 20
    ClickFix and vishing attacks are evolving fast, making social engineering an ever growing threat. See the latest campaigns uncovered by @msftsecurity, @GroupIB & @kaspersky; and how @arsen helps train your team. πŸ‘‡
    Image
    Weekly Cyber Digest - Week of July 20, 2026
    From linkedin.com
    54
  • user avatar
    Arsen Security
    @arsen
    Jul 10
    🚨 @okta details a vishing campaign where @Microsoft365 users are tricked into enrolling attacker-controlled Entra passkeys. Time to test these workflows with company-scale vishing simulations. πŸ‘‡
    Image
    okta.com
    Vishing actors target Entra passkey enrollment | Okta Threat Intelligence
    74
  • user avatar
    Arsen Security
    @arsen
    Jul 8
    πŸ’‘ClickFix is a type of social engineering attack that makes people run malware on their own without the attacker needing to use an exploit. Learn more: arsen.co/en/resources/c…
    user avatar
    Unit 42
    @Unit42_Intel
    Jul 6
    We are tracking a MaaS #ClickFix operation using Polygon #blockchain as a resilient C2 config store. So far, 130+ compromised sites with 15 rotating C2s. Victim telemetry is periodically exfiltrated and stage 3 execution drops an infostealer. Details at bit.ly/4fmKZ8g
    Code snippets from left to right: "Blockchain for C2 fetching" shows JavaScript code for obtaining servers and fetching data from a blockchain. "Screenshot Exfiltration" includes code for capturing and sending screenshots to a server. "Dynamic Clipboard Payload Injection" demonstrates code for injecting and executing clipboard content. Each section is annotated to highlight its purpose.
    The image displays a screenshot of computer code with annotations. It includes highlighted text pointing to the "Rotating C2 domains," "ClickFix Lure," and "Clipboard payloads."
    The image shows a screenshot of the JokerStat operator login page. It features fields for email address and password and a human verification challenge. Text annotations note "One of the 15 C2 domains," "Every C2 domain runs the same clone," and "Support for MaaS kit." A smaller overlay mentions Telegram support.
    75
  • user avatar
    Arsen Security
    @arsen
    Jul 6
    Your finance teams are under attack. AI-assisted voice phishing and deepfake calls are driving fraudulent transfer approvals. Awareness isn't enough. Train the right reflex.
    Why Train Financial Services Teams Against Vishing
    Why Train Financial Services Teams Against Vishing
    From arsen.co
    55
  • user avatar
    Arsen Security
    @arsen
    Jun 15
    #Web3 @Humanityprot & @Quantstamp dropped a thorough postmortem on the "$H" token compromise. Root cause? Spear-phishing. No technical vulnerability was exploited, just one targeted email. Our breakdown below πŸ‘‡
    user avatar
    Humanity
    @Humanityprot
    Jun 12
    Article cover image
    Article
    $H Incident: Tooling Linked to North Korean Actors
    Today we’re publishing the findings of the independent investigation conducted by @Quantstamp, Inc into the $H token compromise on June 8, 2026. Quantstamp's findings show that the attacker used...
    341
Advertisement
Advertisement